惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Fortinet All Blogs
C
Check Point Blog
GbyAI
GbyAI
博客园 - 司徒正美
爱范儿
爱范儿
N
Netflix TechBlog - Medium
H
Hacker News: Front Page
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Security Latest
Security Latest
C
Cyber Attacks, Cyber Crime and Cyber Security
博客园 - Franky
Recent Announcements
Recent Announcements
P
Privacy International News Feed
T
Tor Project blog
Y
Y Combinator Blog
有赞技术团队
有赞技术团队
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
G
GRAHAM CLULEY
The Hacker News
The Hacker News
N
News and Events Feed by Topic
I
Intezer
The GitHub Blog
The GitHub Blog
S
SegmentFault 最新的问题
T
The Blog of Author Tim Ferriss
PCI Perspectives
PCI Perspectives
S
Secure Thoughts
P
Proofpoint News Feed
Microsoft Security Blog
Microsoft Security Blog
IT之家
IT之家
T
Threat Research - Cisco Blogs
J
Java Code Geeks
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
D
DataBreaches.Net
Hacker News - Newest:
Hacker News - Newest: "LLM"
Last Week in AI
Last Week in AI
H
Help Net Security
L
LangChain Blog
大猫的无限游戏
大猫的无限游戏
Help Net Security
Help Net Security
S
Schneier on Security
T
The Exploit Database - CXSecurity.com
Google Online Security Blog
Google Online Security Blog
Cyberwarzone
Cyberwarzone
T
Tailwind CSS Blog
V
Vulnerabilities – Threatpost
Forbes - Security
Forbes - Security
Apple Machine Learning Research
Apple Machine Learning Research
O
OpenAI News
AWS News Blog
AWS News Blog
月光博客
月光博客

AI demand is so high, AWS customers are trying to buy out its entire capacity | Network World

Cisco: Latest news and insights 2026 network outage report and internet health check Selector targets the network visibility gap in multi-cloud infrastructure AI reshapes cybersecurity workforce priorities as IT teams brace for new risks Top network and data center events of 2026 How AI is transforming network incident response (and where it still falls short) Google opens TPUs to enterprises beyond its own cloud via Blackstone JV AI, cybersecurity skills top IT pay premiums Startup Bolt Graphics promises 5x performance over Nvidia’s best GPU Wireless security is a battle of AI vs. AI NetOps teams look to AI to automate Day 2 operations Digital twins reshape network and data center management Network outages, power failures strain data center resiliency Five takeaways from Cisco's blowout quarter and what it means to customers Cisco to cut nearly 4,000 jobs despite strong growth in AI, enterprise networking Startup SPAN teams with Nvidia to put data center nodes in your backyard Hard drive shortage affecting enterprise storage needs Wi-Fi 8 is closer than you think. Here’s what you need to know Cisco open-sources agentic AI security spec HPE revamps private cloud stack for enterprises rethinking VMware Versa takes aim at fragmented enterprise security with CSPM, orchestration update, and AI agent controls Red Hat opens Ansible to AI agents, within limits Red Hat offers endless Linux support — for a fee Red Hat: Sovereignty is more than just compliance Tech job postings hit three-year high as AI demand fuels hiring rebound HPE memory server targets compute-heavy and agentic AI workloads PCI group begins work on new spec to support bandwidth-hungry apps like AI, HPC Q&A: Quantum physicist Sonia Fernández-Vidal on why classical computing isn't going anywhere OpenAI-led consortium seeks to address AI processing bottlenecks AWS hit by US-East-1 outage after data center thermal event Gluware's Titan rises to meet Mythos network vulnerability challenge AMD launches AI-targeted PCIe cards for current servers Supply constraints, optical advances dominate Arista's Q1 Lumen advances cloud networking vision with $475M Alkira buy HPE bolsters autonomous network operations for Mist, Aruba Central Netskope launches AI agents for SOC and NOC automation Intel, behind in AI chips, bets on quantum and neuromorphic processors Switch storm coming: Gartner forecasts price hikes, long lead times for enterprise data center switches Extreme moves toward autonomous networking with advanced AI agent, management tools Broadcom bets big on VMware Cloud Foundation 9.1 IBM unveils its blueprint to help enterprises run AI at the core of their business Ruckus Networks on the move again, this time acquired by Belden for $1.85 billion AMD and Intel partner to deliver AI performance advancement Cisco grabs Astrix to secure AI agents Beyond the pitch: A look at Atlético Madrid's connected stadium StarlingX 12.0 is right on time for mixed-hardware edge deployments Cisco nerds out: May the Fourth be with your AI assistant Memory shortage and cost surge push enterprises toward the cloud Extreme Networks: Memory advantage, Wi-Fi 7 and competitive flux drive momentum Scenes from the great data center revolt Enterprise Spotlight: Transforming software development with AI When 170,000 people show up: Network refresh readies Churchill Downs for Kentucky Derby IT certification pay surges as noncertified skills slump QuEra claims quantum error correction breakthrough with 2-to-1 qubit ratio HPE expands ProLiant line with rugged edge servers Deconstructing the data center: A massive (and massively liberating) project Cisco bolsters security, AI support in latest SD-WAN release The era of chatbot AIOps is fading as agentic AI gains traction Auvik bets agentic AI can fill the networking skills gap AI data flows force rethink of data center networking at Backblaze Nvidia's 'AI insurance policy' balances immediate and future AI approaches Cirrascale to offer on-prem Google Gemini models Space data-center news: Roundup of extraterrestrial AI endeavors Network jobs watch: Hiring, skills and certification trends Cisco switch aimed at building practical quantum networks How AI is changing copper, fiber networking Almost 40% of data center projects will be late this year, 2027 looks no better It’s the end of set-and-forget security Google bets on workload-specific TPUs with 8t and 8i launch SUSE bets automated migration can break VMware's grip on virtualization How Zero Networks is closing the network enforcement gap for AI agents Cloudflare wants to rebuild the network for the age of AI agents AI fuels wireless talent shortage Broadcom's Facebook friend will help train it to accelerate AI workloads Data centers are costing local governments billions Equinix offering targets automated AI-centric network operations AI shifts IT roles from operator to orchestrator IBM unveils security services for thwarting agentic attacks, automating threat assessment Maine to put brakes on big data centers as AI expansion collides with power limits Satellite backhaul service Globalstar has a new, rich owner amid challenging market conditions DNS security is often inadequate, and network engineers should get more involved Curious about quantum? Check out training options from ISC2, IBM, AWS and more Cisco just made moves to own the AI infrastructure stack Data centers are moving inland, away from some traditional locations Fixing encryption isn't enough. Quantum developments put focus on authentication Intel: Latest news and insights Linux 7.0 debuts with some big changes for networking Intel secures Google cloud and AI infrastructure deal OpenAI puts part of Stargate project on hold over runaway power costs Broadcom strikes chip deals with Google, Anthropic Cisco to acquire Galileo for AI observability Neoclouds gain momentum in a supply-constrained world Yael Nardi joins Minimus as Chief Business Officer to head growth strategy Nvidia Rubin GPUs may be delayed, slowing the next phase of AI infrastructure What is AI networking? How it adds intelligence to your infrastructure Google owns the most AI compute, and it built it its way Aria Networks raises $125M and debuts its approach for AI-optimized networks Intel bets on Terafab to help it reassert itself in the AI chip race New v2 UALink specification aims to catch up to NVLink Cisco joins Anthropic’s multivendor effort to secure AI software
Lumen: Upstream network visibility is enterprise security's new front line
2026-04-09 · via AI demand is so high, AWS customers are trying to buy out its entire capacity | Network World

The cybersecurity industry has spent years debating whether endpoint detection and response (EDR) is sufficient. Lumen Technologies is now making the case that the question itself is outdated. Its 2026 Defender Threatscape Report argues that the decisive signals in modern attacks no longer appear on endpoints at all. They appear upstream, in the network infrastructure that attackers build, test and activate long before a breach is detected inside the enterprise.

The report is authored by Black Lotus Labs, Lumen’s threat research and operations arm. The company operates one of the world’s largest internet backbone networks and claims transit visibility into 99% of all public IPv4 addresses. Black Lotus Labs monitors more than 200 billion NetFlow sessions and 1 billion DNS sessions daily, tracks 2.3 million unique threats and 46,000 C2 (command and control) servers per day, and executed more than 5,000 C2 disruptions in 2025 alone.

Top findings from the report:

  • Generative AI is enabling threat actors to iterate and regenerate malicious infrastructure at machine speed, compressing the window between exposure and impact.
  • Attackers shifted to internet-exposed edge devices including routers, VPN gateways and firewalls, which offer limited forensic capabilities and operate outside traditional endpoint security visibility.
  • Criminal and nation-state crews are industrializing proxy networks using compromised SOHO (small office/home office) devices, hijacking residential IP space to bypass Zero Trust and geolocation controls.
  • The Kimwolf botnet launched DDoS attacks reaching 30 Tbps, roughly 30 times the record observed just one year earlier.

Above all, the report highlights the critical role the network plays in detecting attacks.

“The network is a critical detection layer,” Michelle Lee, senior director of threat intelligence, Black Lotus Labs at Lumen, told Network World. “We can see adversaries build their networks long before they use them in a breach, and so [we have] the network as detection, as the adversaries spin up highly professionalized and intentional ways to traverse the internet. Using that to give us clues into where threat actors are going on their targets, and where they may be covering their tracks elsewhere, is a key piece of the puzzle.”

Why the network layer is critical

Traditional security operations rely on post-infection signals. An endpoint alerts, then an analyst investigates. The problem is timing. By the time an alert triggers on an endpoint, the attacker’s preparation, including scanning, infrastructure rotation and proxy formation, is already complete.

Lumen’s position on the internet backbone changes that equation. The focus is on backbone-level telemetry, where the largest ISPs interconnect. 

At backbone scale, NetFlow metadata reveals patterns that enterprise deployments cannot surface. Lee explained that the structure of networks that adversaries have to create in order to have uptime and cover their tracks are patternable, often in NetFlow with other third-party telemetry. 

“This is not packet information, this is all NetFlow metadata,” she said. “We have a large cluster where we process this information and run machine learning and other heuristic models over that data to detect adversary behavior.”

The Raptor Train botnet illustrates the detection advantage. Raptor Train was a People’s Republic of China state-sponsored botnet that, at its peak, managed more than 200,000 compromised IoT and SOHO devices through a three-tier command structure. Lee noted that the backbone-level NetFlow data showed how the adversary was standing up this network across the internet. That includes command and control, malware deployment, and uptime verification.

“You could really see the structure of how this network was connecting across the backbone and through IoT devices in residential networks around the world,” she said. “That’s the kind of visibility you can get through NetFlow.”

The edge is a primary target

According to the report, EDR solutions were deployed by 91% of organizations in 2025, covering 72% of in-scope devices on average. That coverage pushed attackers toward infrastructure that sits outside endpoint visibility entirely.

CISA, the UK’s National Cyber Security Centre, and the Australian Signals Directorate have each published guidance in the past year documenting the shift toward edge device targeting. Fortinet and Cisco ASA devices were the top targets for brute force activity in Q4 2025, followed by exposed VPN concentrators, SonicWall appliances, and Palo Alto devices.

The J-magic campaign illustrates how far this targeting has evolved. Attackers planted a passive listener directly onto enterprise-grade Juniper routers using a custom malware variant, executed entirely in memory with no firmware modification and no persistent disk artifacts. Using eBPF, the malware passively inspects all inbound TCP traffic on a specified interface and port. When a packet matches one of five predefined conditions, it forks a child process and establishes an encrypted reverse shell. No suspicious process ever appears on a user machine. Endpoint-based detection sees nothing.

“We watch some creative threat activity at the edge, especially when paired with highly skilled obfuscation networks,” Lee said. “Threat actors traverse the internet to appear to be coming from a work-from-home router or network, and then potentially perform a live-off-the-land attack.”

Attackers are hiding in home networks

Compromised home routers, IoT devices, and VPS hosts have become foundational to how modern attacks are staged and executed. By routing malicious traffic through residential IP space, attackers bypass geofencing, ASN-based blocking, and zero-trust location signals. The traffic looks like it originates from a legitimate home or small business, not a threat actor.

Lee described the issue as a double-edged problem for defenders. One edge is the home network devices, and the other is the edge of enterprises. She noted that attackers exploit both. They compromise SOHO devices to build proxy networks, then use those networks to attack enterprise edge infrastructure.

The scale of vulnerable hardware makes this tractable for attackers. Lee noted that there are enough devices on the market today that have exposed identity management vulnerabilities to the internet, or are vulnerable to known CVEs, that adversaries are able to roll those into networks pretty quickly. For example, the NSOCKS proxy service maintained a daily average of 35,000 active bots across 180 countries in 2025, with two-thirds of proxies based in the US.

“Threat actors can, for pennies, cycle through IP addresses to get fresh positive-reputation IP addresses minute to minute and use them for their wares at various parts of the attack lifecycle, whether it’s brute forcing, whether it’s leveraging known positive credentials, or whether it’s exfiltrating information at the end of the attack chain,” she said.

Kimwolf: How a botnet scaled to 30 Tbps

The Kimwolf botnet is the clearest illustration of what residential proxy exploitation looks like at operational scale. Kimwolf emerged in late 2025 as a breakaway from Aisuru, at the time the most powerful DDoS botnet on the internet, and ultimately launched attacks reaching 30 Tbps, roughly 30 times the largest DDoS attack observed one year earlier.

Using the network layer was critical to understanding how Kimwolf was constructed.

“We were able to identify a net new network stemming out of IPIDEA and other residential proxy networks,” Lee explained. “The Kimwolf operators were exploiting a vulnerability in IPIDEA which allowed for LAN pivoting, so a threat actor could essentially buy residential proxy access, jailbreak it, pivot out into the LAN, and recruit other devices in the LAN into their botnet.”

The architecture reflects a logistics-first approach to botnet management. C2 nodes are designed to burn quickly. When null-routing disrupts a node, operators react within hours, sometimes minutes, standing up replacements and triggering mass malware re-downloads across the botnet. Through coordinated null-routing, more than 550 Aisuru and Kimwolf C2 nodes were disrupted in four months. The speed and scale of Kimwolf’s recovery cycles show how future large-scale botnets will evolve under pressure, rebuilding faster than defenders can respond.

What defenders should do differently

The threat data tells a consistent story. Attackers are operating in spaces defenders are not watching. Edge devices go unmonitored, residential IP space is trusted by default, and indicator of compromise (IOC) lists lag weeks behind infrastructure that rotates in minutes. Closing those gaps does not require replacing existing security investments. It requires extending visibility into the parts of the network where attacks are actually staged.

Network security professionals should consider the following best practices:

  • Treat edge devices as crown jewels. VPN gateways, routers, and firewalls warrant the same patching discipline and access controls applied to domain controllers.
  • Replace IOC-to-IOC blocking with network-level pattern detection. Static indicator lists cannot keep pace with infrastructure that rotates continuously.
  • Flag residential and SOHO IP space as a threat signal, not a trust signal. The threat data clearly shows the risk from SOHO networks.

“It’s really important that defenders are preparing themselves with a rich understanding of where residential proxy networks or a specific nation-state network is coming in contact with their network, so that an IP address that looks to be a legitimate SOHO router probing an important asset, that flag can go: this may be part of a malicious network,” she said.

SUBSCRIBE TO OUR NEWSLETTER

From our editors straight to your inbox

Get started by entering your email address below.